v0.1.0 — Initial public release
Initial public release of Detect-Forge — an AI-native detection-engineering toolkit. One install, one config, one CI step.
Install
pip install detect-forgeHighlights
stale— score Sigma/Elastic rules for ATT&CK technique staleness (timestamp drift, semantic drift, opt-in LLM diff proposals).coverage— map rules to the ATT&CK matrix (full/shallow/gap) with CTID-weighted priority gating and Navigator export.backtest— adversarial replay against the bundled Mordor corpus with Sigma + Elastic (EQL/KQL) matchers and two CI gates.audit— one-step composite gate over stale + coverage + backtest.- Ships as a PEP 561 typed package; runs as a GitHub Actions CI gate. No data leaves your environment.
See the CHANGELOG for the full list, including the correctness and security hardening in this release.
Full metadata: https://github.com/jamesbower/Detect-Forge/blob/v0.1.0/README.md